Security features bypass in GitLab Enterprise Edition and Gitlab Community Edition - CVE-2021-39881
Published: October 5, 2021
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to the application may let a malicious user create an OAuth client application with arbitrary scope names. A remote authenticated attacker can trick a victim to authorize the malicious client application using the spoofed scope name and description.
Affected software
Gitlab Community Edition
How to mitigate CVE-2021-39881
Gitlab Community Edition - addressed in versions 14.1.7, 14.2.5, 14.3.1